logo

Malvertising Campaign Targets Slack in Google Search Engine

ID: c04f6a15-8a01-536b-8ed5-b7c498b422cb

STIX ID: report--c04f6a15-8a01-536b-8ed5-b7c498b422cb

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2024-08-22

Date Updated: 2026-04-23

Author: Alan J

...
...

Researchers uncovered a sophisticated malvertising campaign that used fraudulent Google search ads impersonating Slack to funnel victims through layered redirects and cloaked landing pages to a malicious domain (slack-windows-download.com) hosting a download that deployed the SecTopRAT remote access/stealer. The actors employed evasion TTPs — including ad ‘cooking’, click-tracking abuse, and cloaking — to avoid detection, indicating a targeted, active malware distribution effort with potential data-theft impact on affected users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.